Technology Category
- Analytics & Modeling - Real Time Analytics
- Infrastructure as a Service (IaaS) - Cloud Computing
Applicable Functions
- Logistics & Transportation
Use Cases
- Cybersecurity
- Real-Time Location System (RTLS)
Services
- Cybersecurity Services
About The Customer
The customers in this case study are clients of Exiger, a global authority on regulatory compliance. These clients span various industries and rely on Exiger’s expertise and tools to manage and mitigate cybersecurity risks within their ecosystems. They are particularly concerned with vulnerabilities that could be exploited by hackers, including those linked to powerful nation-state actors. In 2021, these clients faced threats from two cyber espionage groups believed to be affiliated with the Chinese government, which created over 16 different malware families to target Pulse Secure VPN.
The Challenge
In late September 2022, the IT Security community and Microsoft confirmed the investigation of a significant set of vulnerabilities, including two zero days, affecting Microsoft Exchange Server (2013, 2016, and 2019). These zero-day exploits are serious as they are computer-software vulnerabilities previously unknown to those who should be interested in its mitigation, like the vendor of the target software. Until the vulnerability is mitigated, hackers can exploit remotely nearly any programs, data, additional computers, or a network operating on the impacted system(s). The cybersecurity of supply chains has become a key risk area, with vulnerabilities like those seen with Microsoft Exchange Server and recent breaches such as SolarWinds and Accellion demonstrating how software can become a Trojan horse, turning protective products into ecosystem-wide threats. Over the last three years, Exiger’s clients have seen over 30 severe vulnerabilities targeted by hackers, often linked with powerful nation-state actors.
The Solution
In response to one of the worst cyber breaches in the last decade, Exiger’s clients leveraged the company's live, real-time cyber exploration tools to identify vendors in their ecosystems that were potentially responsive to the recently identified Microsoft Exchange Server zero day. Utilizing the Supply Chain Explorer Cyber module, Exiger clients were able to instantaneously identify and assess the criticality of the threat in their environment. The DDIQ Cyber Analysis tool created a real-time view of the threat and the vulnerabilities to clients, allowing for risk-based mitigation and stopping the threat where it mattered most.
Operational Impact
Quantitative Benefit
Case Study missing?
Start adding your own!
Register with your work email and create a new case study profile for your business.
Related Case Studies.
![](/files/casestudy/Leading-Tools-Manufacturer-Transforms-Operations-with-IoT.png)
Case Study
Leading Tools Manufacturer Transforms Operations with IoT
Stanley Black & Decker required transparency of real-time overall equipment effectiveness and line productivity to reduce production line change over time.The goal was to to improve production to schedule, reduce actual labor costs and understanding the effects of shift changes and resource shifts from line to line.
![](/files/casestudy/Jaguar-Land-Rover-Speeds-Order-to-Cash-Cycle.png)
Case Study
Jaguar Land Rover Speeds Order-to-Cash Cycle
At Jaguar Land Rover, vehicles physically move around the facility for testing, configuration setting, rework and rectification, leading to a longer search time to get each vehicle to its next process facility. The main goal is to minimize the vehicles' dwell time between end of line and the delivery chain which was previously a manually intensive process. Jaguar Land Rover's goal was to build on the success of an earlier RFID project and improve the efficiency of delivering vehicles to meet dealer orders.
![](/files/casestudy/Enel-Secures-Italian-Power-Generation-Network.png)
Case Study
Enel Secures Italian Power Generation Network
Electric energy operators around the world are working to increase the reliability and cyber resiliency of their systems. This includes Enel, a global power company that manages and monitors the Italian power grid. This grid:• Serves 31 million customers• Has a net installed energy capacity exceeding 31 gigawatts• Includes more than 500 power generation plants,including hydroelectric, thermoelectric, and wind• Is managed and monitored by Enel 24/7/365• Is operated by Terna, the Italian Transmission System Operator (TSO)Enel is responsible for the availability of the grid’s underlying ICS and industrial network. It also manages Regional Control Centers and Interconnection Centers which connect with the TSO. The TSO manages the flow of energy to the grid plus controls and remotely regulates the power generation of power plants, increasing and decreasing power production as required. The complex system of interaction and cooperation between Enel and the TSO has strong security implications as well as operational and business challenges.
![](/files/casestudy/Securing-the-Connected-Car-Ecosystem.png)
Case Study
Securing the Connected Car Ecosystem
In-vehicle communications and entertainment system hosts high-value or sensitive applications. API libraries facilitate communication and sharing of vehicle data. These API libraries are vulnerable to reverse engineering and tampering attacks and may even result in loss of passenger safety. Attackers can inject malware that may be able to migrate to other in-car networks such as the controller-area-network (CAN) bus which links to the vehicle’s critical systems. Software provided for dealers to interface with cars through the OBD2 port is vulnerable to reverse engineering and tampering attacks. Hackers may be able to abuse these tools to inject malicious code into the ECUs and CAN bus. Attackers can lift the cryptographic keys used, and use that to build their own rogue apps/software. Their cloned version of the original app/software may have altered functionality, and may intend to gain access to other in-car networks.
![](/files/casestudy/Improve-Postal-Mail-and-Package-Delivery-Company-Efficiency-and-Service.png)
Case Study
Improve Postal Mail and Package Delivery Company Efficiency and Service
Postal mail and package delivery company wanted to replace legacy yard management system, increase inbound and outbound yard velocity, improve priority parcel delivery time and accuracy, reduce workload and overtime, reduce driver detention and measure performance and utilization of yard resources.
![](/files/casestudy/Secure-and-Cloud-based-Data-Marketplace.png)
Case Study
Secure and Cloud-based Data Marketplace
The great promise of new connected concepts of industry like 'Industry 4.0' is their ability to deliver a historically unparalleled level of responsiveness and flexibility. While modern supply chains are already heavily integrated and designed to be fluid and fast moving, a large swathe of manufacturing still remains beholden to economies of scale, large production runs, and careful preplanning.The Industrial Internet of Things (IIoT) is set to change this by allowing small-batch or even custom manufacturing on a truly industrial scale. With machines whose functions are not set in stone, but flexible and determined by their operating software and with a new form of connectivity bringing industrial engineers, product manufacturers, and end users closer together than ever before. Ad-hoc adjustments to automotive parts, for example, during active product runs or the bespoke manufacturing of custom sneakers become very viable options indeed.Much of this remains a theoretical vision, but IUNO, the German national reference project for IT security in Industry 4.0 demonstrates the new capabilities in action with a secure technology data marketplace running a smart drinks mixer.